CVE-2019-10657: Grandstream GWN7000 Firmware

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply config request.

Affected products

  • Grandstream GWN7000 Firmware: before 1.0.6.32 (fixed in 1.0.6.32)
  • Grandstream GWN7610 Firmware: before 1.0.8.18 (fixed in 1.0.8.18)

Published 2019-03-30. Last modified 2026-06-17.